πŸ›‘οΈ WordPress Vulnerability Database

Live intelligence from CISA KEV, NVD, and WPScan — updated daily. Check if your plugins and themes have known CVEs.

40,383
Total CVEs
66
CISA KEV (Actively Exploited)
Aug 26, 2026
Last Updated

40,383 vulnerabilities found (page 1106 of 1616)

CVE IDPlugin / ThemeSeverityCVSSDescriptionFixed InSource
f648a9ca-a72f-418e-bf1b-ad4ecc27d365
< 2.8.8.1
MEDIUM 5.3 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposu… wordfence
f6445bcc-b12d-419f-beca-8ee617465bf4
< 2.35
MEDIUM 5.3 The Cookies and Content Security Policy plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers… wordfence
f6374cda-5aa2-4a2c-8d20-5641cfc33529 MEDIUM 5.3 The WSM Downloader for WordPress is vulnerable to domain bypass due to insufficient hostname validation in the wsmd_user… wordfence
f62d28bd-fa33-4f0b-a116-5aacc05bfa3a
< 1.3.73
MEDIUM 5.3 The Appointment Hour Booking plugin for WordPress is vulnerable to CAPTCHA bypass in versions up to, and including, 1.3.… wordfence
f62a9ca0-7077-410f-b005-175348acd133
< 3.3.0
MEDIUM 5.3 The SEO SIMPLE PACK plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.2… wordfence
f61b9de5-5c37-4efb-ad1c-006e9fc05bc2
< 2.7
MEDIUM 5.3 The CRM Memberships plugin for WordPress is vulnerable to unauthorized membership tag creation due to a missing capabili… wordfence
f6092987-5f60-42ac-9636-e1e0a2c85147
< 2.7.4
MEDIUM 5.3 The package http-cache-semantics is vulnerable to Regular Expression Denial of Service (ReDoS) in versions before 4.1.1 … wordfence
f5fda67f-2bec-4439-8f7b-892fd89b9390
< 7.0.2
MEDIUM 5.3 The Woocommerce OpenPos plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ch… wordfence
f5f3f079-ccea-47a2-9441-29d8d8c77a5c
< 4.14.2
MEDIUM 5.3 The Jupiter X Core plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a func… wordfence
f5e490df-958c-4f3d-9ddb-68e82c03f495
< 1.36
MEDIUM 5.3 The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Sensitive Information Exposure in all ve… wordfence
f5e400f8-35b4-4be4-bb00-c59e14ddd57f
< 23.1.3
MEDIUM 5.3 The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Soc… wordfence
f5e023d6-7a8c-4f18-941d-1a133d8a353e
< 4.0.50
MEDIUM 5.3 The Sendinblue for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
f5dc2350-0dd3-4233-983f-3c7d294d18d1
< 2.3.3
MEDIUM 5.3 The Product Attachment for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in versions … wordfence
f5a9d976-5dee-437e-9fdf-1edffb8574b7 MEDIUM 5.3 The Twitch Player plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a funct… wordfence
f5a1c6bb-2054-40ad-b7fc-0a868b2c5eab MEDIUM 5.3 The WooTumblog plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function… wordfence
f58fac2a-d1f3-47f2-8abb-afe11ae2689a MEDIUM 5.3 The Gift Cards for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability che… wordfence
f57dc0fe-07f3-457e-8080-fe530f6a9f01
< 1.11.3
MEDIUM 5.3 The Open Graph plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including… wordfence
f5733ed6-a6f8-40f1-80b2-ab09fca02791
< 4.3.4
MEDIUM 5.3 The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio… wordfence
f563b9ee-f33c-4d51-9db7-a3005c290fa7
< 3.1.15
MEDIUM 5.3 The BigHearts theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function i… wordfence
f563412d-5708-43c4-a44e-7645c5b4f835
< 3.1.1
MEDIUM 5.3 The FlxWoo plugin for WordPress is vulnerable to Payment Bypass in all versions up to 3.1.1 (exclusive). This makes it p… wordfence
f53700f8-9a9e-449c-8f7f-38724d74bd49
< 2.4.11
MEDIUM 5.3 The wpForo Forum plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a functi… wordfence
f530dced-01bc-4555-b84f-705d6049956b
< 6.7.0.66
MEDIUM 5.3 The Quiz Maker Business plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and … wordfence
f52f1866-cd9d-4443-85c8-e0e7e50f3fbc
< 3.5.4
MEDIUM 5.3 The JetFormBuilder β€” Dynamic Blocks Form Builder plugin for WordPress is vulnerable to unauthorized access due to a mi… wordfence
f50c31df-56d0-4c34-a93c-56198fe91b36
< 2.1.9
MEDIUM 5.3 The MaxiBlocks Builder plugin for WordPress is vulnerable to arbitrary media file deletion due to insufficient file owne… wordfence
f50bca0a-7089-4b4e-820f-d311fdb88cf1
< 2.0.6
MEDIUM 5.3 WordPress 2.0.2 through 2.0.5 allows remote attackers to obtain sensitive information via a direct request for (1) 404.p… wordfence
← Prev 1103 1104 1105 1106 1107 1108 1109 Next →

Is your WordPress site affected?

EzyAudit AI automatically detects your installed plugins and checks them against this database — in seconds.

Scan My Website →
Scroll to Top